diff --git a/.github/workflows/codeql-javascript.yaml b/.github/workflows/codeql-javascript.yaml new file mode 100644 index 00000000..43809b7a --- /dev/null +++ b/.github/workflows/codeql-javascript.yaml @@ -0,0 +1,36 @@ +name: codeql-javascript + +permissions: { } + +on: + push: + branches: + - main + pull_request: + branches: + - main + schedule: + - cron: '22 5 * * 1' + +concurrency: + # Cancels in-progress runs only for pull requests + group: ${{ github.workflow }}-${{ github.head_ref || github.run_id }} + cancel-in-progress: true + +jobs: + analyze: + name: Analyze JavaScript + runs-on: 'ubuntu-latest' + permissions: + security-events: write + steps: + - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + with: + persist-credentials: false + - uses: github/codeql-action/init@95e58e9a2cdfd71adc6e0353d5c52f41a045d225 # v4.35.2 + with: + languages: javascript + build-mode: none + - uses: github/codeql-action/analyze@95e58e9a2cdfd71adc6e0353d5c52f41a045d225 # v4.35.2 + with: + category: "/language:javascript-typescript"